Latent Stability Analysis of Malware Representations Under Feature-Space Perturbations
Bamidele Ajayi, Ken McGarry
cs.CR, cs.AI
Submitted: 2026-07-27
License: http://creativecommons.org/licenses/by-nc-sa/4.0/
The gist: Static malware detectors are commonly evaluated using clean-sample metrics such as accuracy, F1, ROC AUC, and PR AUC.
Terminology
Abstract
Static malware detectors are commonly evaluated using clean-sample metrics such as accuracy, F1, ROC AUC, and PR AUC. However, these metrics provide limited insight into how learned malware representations behave when feature vectors are perturbed, how close samples move toward uncertain decision regions, or whether compressed representations preserve security-relevant structure. This paper presents a latent-stability analysis pipeline for malware perturbation assessment in EMBER feature space. The pipeline compares full EMBER features, PCA-based compression, beta/denoising variational autoencoder representations, Mandelbrot-inspired escape-time descriptors, and a PINN-style latent-flow module. We define Latent Escape Divergence (LED) to measure changes in escape-time profiles under perturbation, and use PINNFlow-derived residual, velocity, risk, and gradient-shift metrics to characterize latent movement. Experiments are conducted on EMBER static PE feature vectors using 180,000 training samples, 180,000 test samples, and 240,000 holdout samples. Full EMBER features achieve the strongest clean classification performance with ROC AUC of 0.9962 and F1 of 0.9713, while PCA-64 is the strongest compressed baseline with ROC AUC of 0.9846 and F1 of 0.9347. The proposed VAE+Mandelbrot+PINNFlow representation does not outperform these baselines for clean classification, but it provides additional diagnostic value under controlled feature-space perturbation probes.
Sources
- EMBER: An Open Dataset for Training Static PE Malware Machine Learning Models
- EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers
- Malware Detection by Eating a Whole EXE
- Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
- Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection
- secml-malware: Pentesting Windows Malware Classifiers with Adversarial EXEmples in Python
- MAB-Malware: A Reinforcement Learning Framework for Attacking Static Malware Classifiers
- A survey on practical adversarial examples for malware classifiers
- UMAP: Uniform Manifold Approximation and Projection for Dimension Reduction
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs